Apache mod_php File Descriptor Leakage Vulnerability
BID:6117
Info
Apache mod_php File Descriptor Leakage Vulnerability
| Bugtraq ID: | 6117 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 06 2002 12:00AM |
| Updated: | Nov 06 2002 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Georgi Guninski. |
| Vulnerable: |
Apache Apache 1.3.26 |
| Not Vulnerable: | |
Discussion
Apache mod_php File Descriptor Leakage Vulnerability
A vulnerability has been discovered in the mod_php module available for Apache web servers that may, under some circumstances, leak file descriptor information. By exploiting this vulnerability it may be possible for a remote attacker to reuse file descriptors used by the httpd daemon, effectively taking control of TCP port 80.
Exploitation of this issue may allow an attacker to bind a malicious server in place of Apache httpd server.
It should be noted that this issue is exploitable only if the 'safe_mode' PHP option is disabled.
A vulnerability has been discovered in the mod_php module available for Apache web servers that may, under some circumstances, leak file descriptor information. By exploiting this vulnerability it may be possible for a remote attacker to reuse file descriptors used by the httpd daemon, effectively taking control of TCP port 80.
Exploitation of this issue may allow an attacker to bind a malicious server in place of Apache httpd server.
It should be noted that this issue is exploitable only if the 'safe_mode' PHP option is disabled.
Exploit / POC
Apache mod_php File Descriptor Leakage Vulnerability
A sample proof of concept is provided in the referenced advisory.
A sample proof of concept is provided in the referenced advisory.
Solution / Fix
Apache mod_php File Descriptor Leakage Vulnerability
Solution:
An unofficial patch has been made available by George Guninski. Further details are in the referenced advisory.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Apache Apache 1.3.26
Solution:
An unofficial patch has been made available by George Guninski. Further details are in the referenced advisory.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Apache Apache 1.3.26
-
George Guninski guninski-httpd.patch
http://downloads.securityfocus.com/vulnerabilities/patches/guninski-ht tpd.patch
References
Apache mod_php File Descriptor Leakage Vulnerability
References:
References:
- Fun with mod_php/Apache 1.3, yet Apache much better than II$ (Georgi Guninski
)